IE BUG, Mozilla DOS?

2005-11-21 Thread admin
The IE bug shown in the advisory here http://www.computerterrorism.com/research/ie/ct21-11-2005 seems to have a DDOS like effect on mozilla sending pc usage to 99 % until mozilla either crashes or gives way.

Gadu-Gadu several vulnerabilities (version <= 7.20)

2005-11-21 Thread Jaroslaw Sajko
21/11/05 Gadu-Gadu instant messenger several vulnerabilities I. INTRODUCTION During the preparation of the materials about instant messengers security for the security conference we have checked current state of the Gadu-Gadu (http://www.gadu-gadu.pl) security. There was discovered a several new

Computer Terrorism Security Advisory (Reclassification) - Microsoft Internet Explorer JavaScript Window() Vulnerability

2005-11-21 Thread securityadvisory
Computer Terrorism (UK) Security Advisory (Reclassification) :: CT21-11-2005 - Title:Microsoft Internet Explorer JavaScript Window() Vulnerability Author: S. Pearson Organisation: Computer

[SECURITY] [DSA 904-1] New netpbm packages fix arbitrary code execution

2005-11-21 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 904-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze November 21st, 2005

[SECURITY] [DSA 903-1] New unzip packages fix unauthorised permissions modification

2005-11-21 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 903-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze November 21st, 2005

[SECURITY] [DSA 900-2] New fetchmail packages fix potential information leak

2005-11-21 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 900-2 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze November 21st, 2005

Re: Cisco Clean Access Agent (Perfigo) bypass

2005-11-21 Thread fakemeail
You can be aided by using a firefox plugin called 'user agent switcher'. http://chrispederick.com/work/useragentswitcher/ You can find more user agents by searching google for them. They are have the extension of .xml

Google Search Appliance proxystylesheet Flaws

2005-11-21 Thread H D Moore
This document can be found online at: - http://metasploit.com/research/vulns/google_proxystylesheet/ Title: Google Search Appliance proxystylesheet Flaws Release Date: November 21, 2005 Patch Date: August 16, 2005 Reported Date: June 10, 2005 Vendor: Google Systems Affected: Google Mini Sear

Metro Olografix Crypto Meeting 2006 CFP

2005-11-21 Thread Angelo Dell'Aera
Metro Olografix, an Italian no-profit association which has been working for spreading the knowledge of information technology and networking since 1994, is looking for high-quality speech submissions for the 2006 edition of the Metro Olografix CryptoMeeting (MOCM). The deadline is set on Decembe

Re: Work in Progress: FileZilla Server Terminal V0.9.4d Buffer Overflow

2005-11-21 Thread inge . henriksen
/* FileZillaDoS.cpp FileZilla Server Terminal 0.9.4d DoS PoC by Inge Henriksen. Read the disclaimer at http://ingehenriksen.blogspot.com before using. Made to work with Microsoft(R) Visual C++(R), to use link "WS2_32.lib". */ #include "stdafx.h" #include #include "Winsock2.h" #define BUFFSIZE 10

[SECURITY] [DSA 811-2] New common-lisp-controller packages fix arbitrary code injection

2005-11-21 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 811-2 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze November 21st, 2005

[SECURITY] [DSA 902-1] New xmail packages fix arbitrary code execution

2005-11-21 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 902-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze November 21st, 2005

Your One-Stop Site For Sony Lawsuit Info

2005-11-21 Thread Larry Seltzer
>From some law student http://www.sonysuit.com/

cracking safes with thermal imaging

2005-11-21 Thread Michal Zalewski
Somewhat on the silly side of life, but some subscribers might find it amusing... and a subset of that subset may even find it relevant to their jobs (hopefully in risk management, but possibly in safe cracking): http://lcamtuf.coredump.cx/tsafe/ Cheers, /mz (pluggity plug) http://lcamtuf.cor

APBoard v [all] ---> [SQL injection]

2005-11-21 Thread ksa_ksa82
hi APBoard v|all|--> [SQL injection] site: http://www.php-zentrale.de MySQL-Error:You have an error in your SQL syntax near '\',40' at line 1 (1064) exploet: http://site.com/apboard/thread.php?id=210&start=[SQL] ### www.s4a.cc abdulmageed ###

Security Advisory: Struts Error Message Cross Site Scripting

2005-11-21 Thread Irene Abezgauz
Background == Struts is an open source framework for building web applications. The core of the Struts framework is a flexible control layer based on standard technologies such as Java Servlets, JavaBeans, resource bundles, and the Extensible Markup Language (XML). Struts can be used with d